You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在XDR高级狩猎中提取Threat Intelligence Verdict?

Defender XDR高级狩猎:EmailUrlInfo表恶意URL查询方案

可行方案说明

你提到的Threat Intelligence Verdict字段确实不在EmailUrlInfo主表中,但可以通过KQL关联其他内置表获取该数据,也能直接筛选出Defender判定为恶意的URL,具体实现如下:

1. 关联UrlClickEvents表获取威胁判定

UrlClickEvents表存储了URL的威胁情报判定结果,可通过Url字段与EmailUrlInfo表关联,提取目标字段:

EmailUrlInfo
| join kind=inner (
    UrlClickEvents
    | where isnotempty(ThreatIntelligenceVerdict)
    | project Url, ThreatIntelligenceVerdict
) on Url
| where ThreatIntelligenceVerdict == "Malicious"
| project Timestamp, SenderFromAddress, RecipientEmailAddress, Url, ThreatIntelligenceVerdict

2. 直接筛选恶意URL的简化写法

若仅需聚焦恶意URL,也可从UrlClickEvents表出发反向关联EmailUrlInfo:

UrlClickEvents
| where ThreatIntelligenceVerdict == "Malicious"
| join kind=inner EmailUrlInfo on Url
| project Timestamp, SenderFromAddress, RecipientEmailAddress, Url, ThreatIntelligenceVerdict

3. 补充:关联UrlEntity表覆盖更多场景

如果部分URL无点击事件记录,可尝试关联UrlEntity表(通过Properties字段提取判定信息):

EmailUrlInfo
| join kind=leftouter (
    UrlEntity
    | project Url, ThreatIntelligenceVerdict = Properties.ThreatIntelligenceVerdict
) on Url
| where ThreatIntelligenceVerdict in ("Malicious", "Suspicious")
| project Timestamp, SenderFromAddress, RecipientEmailAddress, Url, ThreatIntelligenceVerdict

字段取值说明

ThreatIntelligenceVerdict的常见有效值包括:Malicious、Suspicious、Clean、Unknown,可根据需求调整筛选条件。

内容的提问来源于stack exchange,提问作者Katie

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.14 08:27:15